said by kpatz:I haven't seen anything on 11768, yet. You say you're seeing these hits from private (unrouteable) IP addresses? What IPs? Can you see the TTL value in the packets? I bet they're coming from a misconfigured box on the same subnet as you. Or someone's spoofing the source IP in the scans (possible for UDP or ICMP but not likely for TCP since a handshake can't normally occur).
Also, are they TCP or UDP scans?
The unroutable source addresses were things like 192.168.30.126. There are lots from a variety of unrelated routable IPs.